On September 9, 2026, the U.S. Federal Bureau of Investigation (“FBI”) announced the publication of the FBI Cyber Strategy (the “Strategy”).  The Strategy, which “provides a roadmap for defending the American people and the nation’s critical infrastructure in cyberspace,” is broken into four pillars:

  1. Investigate, Disrupt, and Impose Cost on Cyber Adversaries;
  2. Support Victims;
  3. Increase Impact Through Partnerships; and
  4. Enhance FBI’s Cyber Capabilities.

The Strategy may be of interest to organizations as they develop and assess their own threat monitoring and incident response programs, particularly because of the Strategy’s emphasis on the FBI’s continued cooperation and information sharing with the private sector.  For purposes of this blog post, we have focused on the first three pillars, as the fourth pillar primarily focuses on the FBI’s internal capabilities.

Investigate, Disrupt, and Impose Cost on Cyber Adversaries

Although this pillar outlines three separate objectives focused primarily on efforts by the FBI to investigate and take action against threat actors, it also underscores the important role the private sector can play in supporting FBI operations to counter cyber threats.  The Strategy emphasizes that “[v]ictim reporting and the technical evidence that comes with it are essential” to the FBI’s efforts to investigate cyber intrusions and “fuel both individual investigations and the development of disruption operations that extend well beyond any single case.”  The Strategy notes that the FBI’s attribution of threat actors often leverages, among other things, “private-sector telemetry” and “victim reporting.”

Support Victims

This pillar expressly prioritizes supporting and working collaboratively with victims of cybercrime, including by pursuing the following four objectives:

  1. Share Cyber Threat Intelligence with Urgency: The Strategy notes that the FBI “will pursue capabilities that enable urgent, automated sharing of cyber threat intelligence with critical infrastructure owners and trusted private-sector partners.”  Specifically, the FBI will develop “automated indicator-sharing mechanisms that narrow the gap from FBI threat detection to partner notification from days to hours, and from hours to minutes” with the goal of “build[ing] the closer public-private partnership the threat demands, giving victims and trusted partners information they can use to defend systems, contain intrusions, and recover operations.”
  2. Quickly Engage After Incidents: The Strategy emphasizes that the FBI will engage victims with “urgency and operational rigor” and that the FBI “pursues the threat actor, not the victim.”  The Strategy states that the FBI “will notify victims and targeted entities directly and provide intelligence and support to help them defend, contain, and recover” when the FBI identifies that a device, network, or account is being targeted by threat actors.  The Strategy also emphasizes that the FBI will “continue to identify and proactively notify organizations that have been compromised or are at imminent risk,” and continue to invest in establishing relationships before an incident occurs.
  3. Deliver Specialized Capabilities to Victims: The Strategy notes that the FBI will continue to build specialized teams and programs to support victims.  The Strategy identifies various FBI capabilities, including the Industrial Control Systems (“ICS”) Coordinator program, which is designed to build operational technology expertise and support operators of critical infrastructure; the Recovery Asset Team, which works directly with financial institutions to freeze fraudulent transfers; and the Cyber Action Team, which leverages specialized personnel “to respond to major cyber threats and attacks against critical services.”
  4. Facilitate Reporting of Cyber Incidents: The Strategy notes that “[e]arly reporting gives the FBI the evidence, indicators, and financial details needed to advance investigations, notify other victims, and move against the actors responsible.”  To facilitate incident reporting, “all FBI field offices will prioritize building direct relationships with local businesses and organizations to ensure open channels for swift reporting of cyber incidents.”

Increase Impact Through Partnerships

This pillar emphasizes that the FBI is committed to expanding and deepening its relationships with partners, including but not limited to partners across the private sector.  This is further emphasized by the third objective in this pillar, “join[ing] forces with the private sector,” which notes that “[a] steady, two-way exchange of information between the FBI and the private sector is essential to disrupting adversary activity earlier, notifying victims faster, and disrupting infrastructure before campaigns can scale.”  Under this objective, the Strategy re-emphasizes its commitment to “forge direct relationships with industry partners,” including establishing “open channels of communication” and “trusted points of contact before a crisis hits.”

The Strategy further emphasizes that the FBI will seek to strengthen its existing engagement with the private sector through established programs and the expansion of its executive engagement channels.  Specifically, the Strategy cites three established programs (InfraGard, the National Cyber-Forensics and Training Alliance, and the National Defense Cyber Alliance) and three executive engagement channels (CISO Academy, Cyber Executive Summits, and the Leadership in Cyber program).

Conclusion

The FBI Cyber Strategy demonstrates the U.S. government’s continued focus on public-private collaboration to counter cyber and cyber-enabled threats, which was a key theme of the current Administration’s National Cyber Strategy and the National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.  Private organizations should expect continued government engagement on countering cyber threats, and should consider both the potential benefits and risks associated with such engagement.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Ashden Fein Ashden Fein

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel…

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel in criminal, civil, and internal investigations involving cybersecurity, insider risk, and U.S. national security issues.

Ashden regularly counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Ashden frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, extortion and ransomware, and destructive attacks.

Ashden also assists clients from across industries with leading internal investigations and responding to government inquiries related to U.S. national security and insider risks. He frequently represents government contractors in False Claims Act matters involving cybersecurity and national security. Additionally, he advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, FedRAMP, and requirements related to supply chain security.

Before joining Covington, Ashden served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks. Ashden is a retired U.S. Army officer.

Photo of Jim Garland Jim Garland

Jim Garland’s practice focuses on government investigations and enforcement matters, litigation, and cybersecurity. Recognized by Chambers USA as a leading practitioner in both the white collar and cybersecurity categories, Jim draws upon his experience as a former senior Justice Department official to advise…

Jim Garland’s practice focuses on government investigations and enforcement matters, litigation, and cybersecurity. Recognized by Chambers USA as a leading practitioner in both the white collar and cybersecurity categories, Jim draws upon his experience as a former senior Justice Department official to advise clients on sensitive, multidimensional disputes and investigations, often with national security implications. He previously served as co-chair of Covington’s “Band 1”-ranked White Collar and Investigations Practice Group and currently is a member of the firm’s Management and Executive Committees.

Jim regularly represents corporate and individual clients in government investigations and enforcement actions. He has successfully handled matters involving allegations of economic espionage, theft of trade secrets, terrorism-financing, sanctions and export control violations, money laundering, foreign bribery, public corruption, fraud, and obstruction of justice. He has particular expertise advising clients in connection with investigations and disputes involving electronic surveillance and law enforcement access to digital evidence.

Jim has substantial experience litigating high-stakes, multidimensional disputes for clients across a range of industries, including companies in the high-tech, financial services, defense, transportation, media and entertainment, and life sciences sectors. Many of his civil representations have substantial cross-border dimensions or involve parallel government enforcement proceedings in multiple forums.

In conjunction with his investigations and litigation practice, Jim regularly assists clients with cybersecurity preparedness and incident-response matters. He helps clients in assessing security controls and in developing policies and procedures for the protection of sensitive corporate data. He also regularly assists companies in responding to significant cybersecurity incidents, including in connection with criminal and state-sponsored attacks targeting customer and employee data, financial information, and trade secrets.

From 2009 to 2010, Jim served as Deputy Chief of Staff and Counselor to Attorney General Eric Holder at the U.S. Department of Justice. In that role, he advised the Attorney General on a range of enforcement issues, with an emphasis on criminal, cybersecurity, and surveillance matters.

Photo of Micaela McMurrough Micaela McMurrough

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other…

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other complex commercial litigation matters, and she regularly represents and advises domestic and international clients on cybersecurity and data privacy issues, including cybersecurity investigations and cyber incident response. Micaela has advised clients on data breaches and other network intrusions, conducted cybersecurity investigations, and advised clients regarding evolving cybersecurity regulations and cybersecurity norms in the context of international law.

In 2016, Micaela was selected as one of thirteen Madison Policy Forum Military-Business Cybersecurity Fellows. She regularly engages with government, military, and business leaders in the cybersecurity industry in an effort to develop national strategies for complex cyber issues and policy challenges. Micaela previously served as a United States Presidential Leadership Scholar, principally responsible for launching a program to familiarize federal judges with various aspects of the U.S. national security structure and national intelligence community.

Prior to her legal career, Micaela served in the Military Intelligence Branch of the United States Army. She served as Intelligence Officer of a 1,200-member maneuver unit conducting combat operations in Afghanistan and was awarded the Bronze Star.

Photo of Moriah Daugherty Moriah Daugherty

Moriah Daugherty advises clients on a broad range of cybersecurity and national security matters, with a particular focus on risk management and governance, regulatory compliance, incident response and crisis management, and internal and government investigations.

Moriah specializes in counseling clients on a variety…

Moriah Daugherty advises clients on a broad range of cybersecurity and national security matters, with a particular focus on risk management and governance, regulatory compliance, incident response and crisis management, and internal and government investigations.

Moriah specializes in counseling clients on a variety of issues related to cybersecurity risk management and governance, including evaluating security controls, practices, and policies and preparing for cybersecurity incidents and data breaches, including the potential for related investigations, regulatory inquiries, and litigation. She regularly counsels clients on responding to a broad range of cybersecurity incidents, including breaches of personal data and incidents involving extortion and ransomware, targeting and theft of intellectual property by advanced persistent threats, and state-sponsored theft of sensitive U.S. government information.

Drawing on her government experience, Moriah leads cyber-related internal investigations and investigations conducted in response to government inquiries, whistleblower complaints, and threats of litigation, including matters involving allegations of noncompliance with U.S. government cybersecurity regulations and fraud under the False Claims Act.

Prior to becoming a lawyer, Moriah spent eight years working for the Federal Bureau of Investigation and U.S. Department of Justice.

Photo of Ali Cooper-Ponte Ali Cooper-Ponte

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through…

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through both internal and government investigations. She helps clients across industries navigate significant enterprise risks, including insider, criminal, and advanced persistent or nation-state threats, as well as challenges relating to emerging technologies. She has also helped clients proactively engage with or respond to inquiries by the U.S. Department of Justice, state Attorneys General, and the Federal Trade Commission.

In her advisory practice, Ali helps clients strategically manage rapidly-changing regulatory and technological landscapes. She counsels clients on compliance with national security, cybersecurity, data privacy, content moderation, and child exploitation laws. She has particular expertise on issues relating to government access to data, including the Electronic Communications Privacy Act and the Foreign Intelligence Surveillance Act and the Fourth Amendment. She also has significant experience with new Federal and state laws implicating Section 230 of the Communications Decency Act and the First Amendment. Here, her experience spans industries (including the technology, healthcare, cryptocurrency and financial services, and aerospace and defense industries) and includes providing practical advice on new legislation, regulatory frameworks, and court rulings as well as developing legislative proposals and potential challenges to new legislation and government action.

Previously, Ali served in the U.S. Department of Justice as Senior Counsel in the Office of the Assistant Attorney General for the Criminal Division, where she focused on the cyber and child exploitation portfolios, and as a Trial Attorney in the National Security Division’s National Security Cyber Section and the Criminal Division’s Computer Crime and Intellectual Property Section. She joined the Justice Department as part of its inaugural class of Cyber Fellows, which gave her broad exposure to the Department’s work to address cyber and cyber-enabled threats.

Earlier in her career, Ali clerked for Judge José A. Cabranes on the U.S. Court of Appeals for the Second Circuit. Prior to law school, Ali worked as a legal investigations specialist focused on electronic surveillance and law enforcement access issues at a large technology company.

In addition to her regular practice, Ali leverages her experience to counsel pro bono clients engaged in work to protect children and civil liberties.

Photo of Matthew Harden Matthew Harden

Matthew Harden is a cybersecurity and litigation associate in Covington’s New York office. He advises clients on cybersecurity and national security matters, including cybersecurity incident response, crisis management, enterprise risk management and governance, internal investigations, and regulatory compliance.

Matthew helps clients prepare for…

Matthew Harden is a cybersecurity and litigation associate in Covington’s New York office. He advises clients on cybersecurity and national security matters, including cybersecurity incident response, crisis management, enterprise risk management and governance, internal investigations, and regulatory compliance.

Matthew helps clients prepare for and respond to cybersecurity incidents and data security events. He advises on cybersecurity investigations, counsels on incident response strategy, and helps clients assess legal, regulatory, and litigation risks arising from data breaches, network intrusions, ransomware, insider threats, digital threats, and other cyber matters.

Matthew counsels clients on cybersecurity and information security governance. He assists with drafting, designing, and assessing enterprise cybersecurity policies, information security programs, incident response plans, and related procedures. His work includes advising on cybersecurity and privacy compliance obligations, emerging cybersecurity regulations, and legal risks associated with artificial intelligence (AI), Internet of Things (IoT) technologies, and connected products.

As part of his litigation and investigations practice, Matthew draws on his cybersecurity experience to advise clients in high-stakes disputes, internal investigations, and regulatory matters. He represents government contractors in False Claims Act matters involving cybersecurity and national security. He also maintains an active pro bono practice focused on veterans’ rights.

Matthew serves as a Judge Advocate in the U.S. Coast Guard Reserve.

Photo of Alexandra Bruer Alexandra Bruer

Alexandra Bruer is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity and CFIUS Practice Groups.